GLOSSARY / Compliance & Risk

DORA (Digital Operational Resilience Act)

An EU regulation requiring financial entities and their critical ICT providers to demonstrate operational resilience, incident reporting, and third-party risk management.

west Back to Glossary

Definition

shield

DORA (the Digital Operational Resilience Act) is an EU regulatory framework requiring financial entities to demonstrate they can withstand, respond to, and recover from ICT-related disruptions, including cloud outages. It extends direct oversight to critical third-party technology providers, and requires documented resilience testing, incident reporting timelines, and clear exit strategies from any single cloud provider. For firms using AWS, DORA compliance shows up most concretely in disaster recovery planning, tested failover procedures, and evidence of resilience, not just intention.

In Practice

A firm subject to DORA can no longer treat 'we have backups' as sufficient evidence of resilience; auditors expect documented RTO/RPO targets and records of tested, not merely planned, recovery procedures.